Back to blog
·Actionable insights

How to complete a DDQ online in under 15 minutes

Need to complete a DDQ online right now? Upload your questionnaire, get AI-generated answers from your SOC 2 and policies, and export — done in 15 minutes.

How to complete a DDQ online in under 15 minutes

You just got a DDQ in your inbox. The prospect needs it back by Friday. You have 200 questions to answer and half a day of meetings ahead. Sound familiar?

Here's the fastest way to complete a DDQ online — step by step, no demo required.

What you need before you start

Three things:

  1. The DDQ file — Excel, Word, or PDF. Any format works.
  2. Your SOC 2 report — Type I or Type II. This alone covers 40–60% of DDQ questions.
  3. 2–3 security policies — Information Security, Data Retention, and Incident Response are the highest-value documents. Access Control and Business Continuity are useful but not essential for your first run.

If you've already completed DDQs in the past, those are gold — upload them too. Past responses fill gaps that formal policies don't cover.

Step 1: Upload your knowledge base (5 minutes)

Go to FillBase and create a free account. No credit card, no demo call.

Drag and drop your SOC 2 report and policies. The AI processes each document, extracts facts, and indexes them. A typical SOC 2 report takes about 30 seconds to process.

This is a one-time setup. Once your knowledge base is built, every future DDQ uses the same sources — and you can add more documents anytime.

Step 2: Submit the DDQ (2 minutes)

Upload the questionnaire file you received. FillBase parses the structure automatically — it understands column layouts in Excel, nested tables in Word, and form fields in PDF.

Within 60 seconds, you'll see every question extracted and listed, ready for AI-generated answers.

Step 3: Review AI-generated answers (8–10 minutes)

FillBase matches each question against your knowledge base and generates a draft answer with source citations. Every response shows exactly where the answer came from: "SOC 2 Type II, Section 3.4" or "Information Security Policy, page 7."

Here's what you'll typically see:

  • ~70% high-confidence answers — Correct, source-cited, ready to approve. Skim these and click approve.
  • ~20% medium-confidence answers — The AI found relevant information but wants you to verify a detail. Usually needs a 10-second tweak.
  • ~10% flagged for human input — Questions specific to your company that aren't covered by your documents. "What is your RTO?" if you haven't uploaded your BCP, for example.

Focus your time on the flagged answers. The rest is handled.

Step 4: Export and send (1 minute)

Export the completed DDQ in the original format — if the prospect sent an Excel, you get an Excel back. No reformatting, no copy-paste between tools.

Attach it to your reply and move on with your day.

Why this works for transactional DDQs

Most DDQ questions are not unique. We analyzed 1,000+ questions across 87 real questionnaires and found that 50 questions appear in nearly every DDQ. "Do you encrypt data at rest?" "Describe your incident response process." "What is your data retention policy."

Once your knowledge base has answers to these recurring questions, completing a DDQ online becomes a review task instead of a writing task. You're checking answers, not creating them from scratch.

What about online portals (OneTrust, Whistic, etc.)?

If your prospect uses an online portal instead of sending a file, the workflow is slightly different:

  1. Export the questionnaire from the portal (most offer CSV or Excel export)
  2. Complete it in FillBase
  3. Import the answers back into the portal

This adds 5 minutes of export/import time, but you still get AI-generated answers from your knowledge base. We're actively building direct portal integrations — reach out if this is a priority for you.

How this compares to manual completion

ManualWith FillBase
Time per DDQ4–8 hours12–15 minutes
Source citationsManual Ctrl+FAutomatic
Consistency across DDQsDepends on who fills itGuaranteed — same KB, same answers
Format handlingManual reformattingAutomatic
Scales with volumeLinear (more DDQs = more hours)Marginal (review time only)

Frequently asked questions

Can I complete a DDQ online for free? Yes. FillBase's free tier includes 200 requirements per month — enough for 1–2 standard DDQs. No credit card required.

What formats are supported? Excel (.xlsx, .xls), Word (.docx), and PDF. If the prospect sends a Google Sheets link, export it as Excel first.

How accurate are the AI-generated answers? Accuracy depends on your knowledge base quality. With a SOC 2 report and 3–5 policies, expect 85–90% accuracy on the first DDQ. After 3–4 completed questionnaires (with your corrections fed back), accuracy reaches 90–95%.

Is my data secure? Your documents are encrypted at rest and in transit. FillBase never uses your data to train models. See our security practices for details.

What if the DDQ has questions outside my SOC 2 scope? The AI flags these as low-confidence and asks for your input. You answer once, and it's stored in your knowledge base for future DDQs.

Stop spending afternoons on DDQs

Every hour you spend manually completing DDQs is an hour not spent on product, engineering, or closing deals. Complete your next DDQ online with FillBase — free tier, no demo, results in 15 minutes.

Your next enterprise deal shouldn't wait on a spreadsheet

Get started